Hi @VijaySrrie ,
you can leave Splunk to use the correct Time format without forcing a TIME_FORMAT in props.conf.
If Splunk doesn't know one of them add it to datetime.xml following the instructions at https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/Data/Configuredatetimexml
Ciao.
Giuseppe
Hi @VijaySrrie ,
you can leave Splunk to use the correct Time format without forcing a TIME_FORMAT in props.conf.
If Splunk doesn't know one of them add it to datetime.xml following the instructions at https://docs.splunk.com/Documentation/SplunkCloud/8.0.2004/Data/Configuredatetimexml
Ciao.
Giuseppe
Hi @VijaySrrie ,
Perfect!
If you appreciate this solution you can also leave a Karma Point .
Ciao and next time.
Giuseppe
You can go through this link.
https://docs.splunk.com/Documentation/Splunk/8.0.4/SearchReference/Commontimeformatvariables
Please check my sample search with your provided data.
| makeresults | eval date="2020-06-24 03:07:39,997Z|2020-06-24 03:07:39.990Z" , date=split(date,"|") | mvexpand date | eval epochtime = strptime(date,"%Y-%m-%d %M:%H:%S,%3QZ") | eval ReIterated = strftime(epochtime,"%Y-%m-%d %M:%H:%S,%3QZ") | table date epochtime ReIterated
Hope this will help you.
Thanks
Kamlesh Vaghela